<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Fagblogg</title>
    <link>https://www.netsecurity.no/en/technical-blog</link>
    <description>Read about the latest within cybersecurity from Netsecurity.</description>
    <language>en</language>
    <pubDate>Tue, 26 May 2026 09:58:20 GMT</pubDate>
    <dc:date>2026-05-26T09:58:20Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>AI-driven cyberthreats to critical infrastructure - also relevant for Norway</title>
      <link>https://www.netsecurity.no/en/technical-blog/ai-driven-cyberthreats-to-critical-infrastructure</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/ai-driven-cyberthreats-to-critical-infrastructure?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/iStock-1419766496.jpg" alt="AI-driven cyberthreats to critical infrastructure - also relevant for Norway" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: bold;"&gt;State actors and criminal networks are attacking critical infrastructure with increasing precision and speed. AI makes attackers faster, cheaper and harder to detect. For Norwegian businesses in the energy, maritime and public service sectors, this is not a scenario for the future - it's the current threat landscape.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/ai-driven-cyberthreats-to-critical-infrastructure?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/iStock-1419766496.jpg" alt="AI-driven cyberthreats to critical infrastructure - also relevant for Norway" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: bold;"&gt;State actors and criminal networks are attacking critical infrastructure with increasing precision and speed. AI makes attackers faster, cheaper and harder to detect. For Norwegian businesses in the energy, maritime and public service sectors, this is not a scenario for the future - it's the current threat landscape.&lt;/p&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=4452610&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.netsecurity.no%2Fen%2Ftechnical-blog%2Fai-driven-cyberthreats-to-critical-infrastructure&amp;amp;bu=https%253A%252F%252Fwww.netsecurity.no%252Fen%252Ftechnical-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>AI</category>
      <category>OT - Industrial Cybersecurity</category>
      <pubDate>Tue, 26 May 2026 09:58:04 GMT</pubDate>
      <guid>https://www.netsecurity.no/en/technical-blog/ai-driven-cyberthreats-to-critical-infrastructure</guid>
      <dc:date>2026-05-26T09:58:04Z</dc:date>
      <dc:creator>Hans Lie</dc:creator>
    </item>
    <item>
      <title>Command Execution via Drag-and-Drop in Terminal Emulators</title>
      <link>https://www.netsecurity.no/en/technical-blog/command-execution-via-drag-and-drop-in-terminal-emulators</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/command-execution-via-drag-and-drop-in-terminal-emulators?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/image-1.png" alt="Command Execution via Drag-and-Drop in Terminal Emulators" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div style="color: rgba(0, 0, 0, 0.847);"&gt; 
 &lt;p&gt;&lt;span style="line-height: 20.925px;"&gt;Many people may not be aware that terminal emulators such as Tabby, Kitty and xfce4-terminal support dragging and dropping of files into the terminal to insert the file's path directly at the cursor position. While this feature has existed for a while, more people have started to notice this as Claude Code has grown in popularity and &lt;/span&gt;&lt;a href="https://code.claude.com/docs/en/common-workflows#work-with-images."&gt;&lt;u&gt;&lt;span style="color: #467886; line-height: 20.925px;"&gt;allows users to drag and drop files for Claude to process&lt;/span&gt;&lt;/u&gt;&lt;/a&gt;&lt;span style="line-height: 20.925px;"&gt;.&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/command-execution-via-drag-and-drop-in-terminal-emulators?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/image-1.png" alt="Command Execution via Drag-and-Drop in Terminal Emulators" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div style="color: rgba(0, 0, 0, 0.847);"&gt; 
 &lt;p&gt;&lt;span style="line-height: 20.925px;"&gt;Many people may not be aware that terminal emulators such as Tabby, Kitty and xfce4-terminal support dragging and dropping of files into the terminal to insert the file's path directly at the cursor position. While this feature has existed for a while, more people have started to notice this as Claude Code has grown in popularity and &lt;/span&gt;&lt;a href="https://code.claude.com/docs/en/common-workflows#work-with-images."&gt;&lt;u&gt;&lt;span style="color: #467886; line-height: 20.925px;"&gt;allows users to drag and drop files for Claude to process&lt;/span&gt;&lt;/u&gt;&lt;/a&gt;&lt;span style="line-height: 20.925px;"&gt;.&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=4452610&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.netsecurity.no%2Fen%2Ftechnical-blog%2Fcommand-execution-via-drag-and-drop-in-terminal-emulators&amp;amp;bu=https%253A%252F%252Fwww.netsecurity.no%252Fen%252Ftechnical-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Mon, 18 May 2026 06:00:00 GMT</pubDate>
      <guid>https://www.netsecurity.no/en/technical-blog/command-execution-via-drag-and-drop-in-terminal-emulators</guid>
      <dc:date>2026-05-18T06:00:00Z</dc:date>
      <dc:creator>Siddharth Dushantha</dc:creator>
    </item>
    <item>
      <title>Hacklore: The Modern Folklore of Cybersecurity</title>
      <link>https://www.netsecurity.no/en/technical-blog/hacklore-cybersikkerhetens-moderne-folketro</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/hacklore-cybersikkerhetens-moderne-folketro?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/freestocks-I_pOqP6kCOI-unsplash.jpg" alt="Hacklore: The Modern Folklore of Cybersecurity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;span&gt;In cybersecurity, there is a phenomenon we rarely talk about, but that almost everyone has encountered. It’s called hacklore.&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/hacklore-cybersikkerhetens-moderne-folketro?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/freestocks-I_pOqP6kCOI-unsplash.jpg" alt="Hacklore: The Modern Folklore of Cybersecurity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;span&gt;In cybersecurity, there is a phenomenon we rarely talk about, but that almost everyone has encountered. It’s called hacklore.&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=4452610&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.netsecurity.no%2Fen%2Ftechnical-blog%2Fhacklore-cybersikkerhetens-moderne-folketro&amp;amp;bu=https%253A%252F%252Fwww.netsecurity.no%252Fen%252Ftechnical-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 24 Mar 2026 07:17:27 GMT</pubDate>
      <author>john@netsecurity.no (John-André Bjørkhaug)</author>
      <guid>https://www.netsecurity.no/en/technical-blog/hacklore-cybersikkerhetens-moderne-folketro</guid>
      <dc:date>2026-03-24T07:17:27Z</dc:date>
    </item>
    <item>
      <title>Cybersecurity during holiday time: Increased risk with low staffing</title>
      <link>https://www.netsecurity.no/en/technical-blog/cybersecurity-during-holiday-time-increased-risk-with-low-staffing</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/cybersecurity-during-holiday-time-increased-risk-with-low-staffing?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/MDR%20Stills%202.png" alt="Cybersecurity during holiday time: Increased risk with low staffing" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h5&gt;When businesses go on vacation, threat actors wake up. Summer is the peak season for digital attacks - and it's management's responsibility to ensure that someone is still on guard.&lt;/h5&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/cybersecurity-during-holiday-time-increased-risk-with-low-staffing?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/MDR%20Stills%202.png" alt="Cybersecurity during holiday time: Increased risk with low staffing" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h5&gt;When businesses go on vacation, threat actors wake up. Summer is the peak season for digital attacks - and it's management's responsibility to ensure that someone is still on guard.&lt;/h5&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=4452610&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.netsecurity.no%2Fen%2Ftechnical-blog%2Fcybersecurity-during-holiday-time-increased-risk-with-low-staffing&amp;amp;bu=https%253A%252F%252Fwww.netsecurity.no%252Fen%252Ftechnical-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 03 Jun 2025 12:11:07 GMT</pubDate>
      <guid>https://www.netsecurity.no/en/technical-blog/cybersecurity-during-holiday-time-increased-risk-with-low-staffing</guid>
      <dc:date>2025-06-03T12:11:07Z</dc:date>
      <dc:creator>Henrik A. Byberg</dc:creator>
    </item>
    <item>
      <title>Security management for IT-OT integrations and supplier management</title>
      <link>https://www.netsecurity.no/en/technical-blog/effektiv-sikkerhetsstyring-for-it-ot-integrasjoner-og-leverand%C3%B8rh%C3%A5ndtering</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/effektiv-sikkerhetsstyring-for-it-ot-integrasjoner-og-leverand%C3%B8rh%C3%A5ndtering?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/OT%20bilder/iStock-1410786331.jpg" alt="Security management for IT-OT integrations and supplier management" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: bold;"&gt;Recent decades have seen a significant increase in the integration, digitization and streamlining of industrial plants. Businesses now face increasing complexity due to integrations between IT and operational technology (OT), the use of cloud solutions and increased use of 4G and 5G solutions for communication. These developments have revolutionized the way we do business, but have also introduced new challenges related to security. For OT environments in particular, it will be important to address these challenges through a risk-based approach.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Going forward, we will see increased integration to streamline operations. We need to facilitate a secure integration that results in efficient, reliable and secure operations.&lt;/p&gt; 
&lt;p&gt;In this blog post, we address:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;span style="font-weight: normal;"&gt;Challenges with increasing gravity of integrations&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="font-weight: normal;"&gt;The status of vendor security&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="font-weight: normal;"&gt;What's required under the Digital Security Act (NIS2)&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="font-weight: normal;"&gt;How to build a resilient supply chain by applying a risk-based approach&lt;/span&gt;&lt;/li&gt; 
&lt;/ol&gt; 
&lt;br&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/effektiv-sikkerhetsstyring-for-it-ot-integrasjoner-og-leverand%C3%B8rh%C3%A5ndtering?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/OT%20bilder/iStock-1410786331.jpg" alt="Security management for IT-OT integrations and supplier management" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: bold;"&gt;Recent decades have seen a significant increase in the integration, digitization and streamlining of industrial plants. Businesses now face increasing complexity due to integrations between IT and operational technology (OT), the use of cloud solutions and increased use of 4G and 5G solutions for communication. These developments have revolutionized the way we do business, but have also introduced new challenges related to security. For OT environments in particular, it will be important to address these challenges through a risk-based approach.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Going forward, we will see increased integration to streamline operations. We need to facilitate a secure integration that results in efficient, reliable and secure operations.&lt;/p&gt; 
&lt;p&gt;In this blog post, we address:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;span style="font-weight: normal;"&gt;Challenges with increasing gravity of integrations&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="font-weight: normal;"&gt;The status of vendor security&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="font-weight: normal;"&gt;What's required under the Digital Security Act (NIS2)&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="font-weight: normal;"&gt;How to build a resilient supply chain by applying a risk-based approach&lt;/span&gt;&lt;/li&gt; 
&lt;/ol&gt; 
&lt;br&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=4452610&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.netsecurity.no%2Fen%2Ftechnical-blog%2Feffektiv-sikkerhetsstyring-for-it-ot-integrasjoner-og-leverand%C3%B8rh%C3%A5ndtering&amp;amp;bu=https%253A%252F%252Fwww.netsecurity.no%252Fen%252Ftechnical-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Fri, 07 Mar 2025 14:02:29 GMT</pubDate>
      <guid>https://www.netsecurity.no/en/technical-blog/effektiv-sikkerhetsstyring-for-it-ot-integrasjoner-og-leverand%C3%B8rh%C3%A5ndtering</guid>
      <dc:date>2025-03-07T14:02:29Z</dc:date>
      <dc:creator>Daniel Ourom-Swart</dc:creator>
    </item>
    <item>
      <title>Code Execution Through Ghostty Window Title</title>
      <link>https://www.netsecurity.no/en/technical-blog/code-execution-through-ghostty-window-title</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/code-execution-through-ghostty-window-title?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/Featured%20Image%20Ghostty%202.png" alt="Code Execution Through Ghostty Window Title" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;Summary&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;&lt;span&gt;On &lt;/span&gt;&lt;span&gt;December 31, 2024,&lt;/span&gt;&lt;span&gt;version &lt;/span&gt;&lt;span&gt;1.0.1&lt;/span&gt;&lt;span&gt; o&lt;/span&gt;&lt;span&gt;f&lt;/span&gt;&lt;span&gt; the modern terminal &lt;/span&gt;&lt;span&gt;emulator&lt;/span&gt;&lt;/span&gt;&lt;a href="https://github.com/ghostty-org/ghostty"&gt;&lt;span&gt;&lt;span&gt;Ghostty&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span&gt;&lt;span&gt;was released&lt;/span&gt;&lt;span&gt;that patched &lt;/span&gt;&lt;span&gt;a&lt;/span&gt;&lt;span&gt; code &lt;/span&gt;&lt;span&gt;execution vulnerability&lt;/span&gt;&lt;span&gt;, now tracked as &lt;/span&gt;&lt;/span&gt;&lt;a href="https://github.com/ghostty-org/ghostty/security/advisories/GHSA-5hcq-3j4q-4v6p"&gt;&lt;span&gt;&lt;span&gt;CVE-2024-56803&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span&gt;&lt;span&gt;. &lt;/span&gt;&lt;span&gt;While terminals execute commands by design, t&lt;/span&gt;&lt;span&gt;his vulnerability &lt;/span&gt;&lt;span&gt;allowed &lt;/span&gt;&lt;span&gt;for &lt;/span&gt;&lt;span&gt;unintended command execution through the title reporting escape sequence &lt;code&gt;(&lt;/code&gt;&lt;/span&gt;&lt;/span&gt;&lt;code&gt;&lt;span&gt;&lt;span&gt;\e[21t&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;span&gt;&lt;span&gt;&lt;code&gt;)&lt;/code&gt;.&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/code-execution-through-ghostty-window-title?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/Featured%20Image%20Ghostty%202.png" alt="Code Execution Through Ghostty Window Title" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;Summary&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;&lt;span&gt;On &lt;/span&gt;&lt;span&gt;December 31, 2024,&lt;/span&gt;&lt;span&gt;version &lt;/span&gt;&lt;span&gt;1.0.1&lt;/span&gt;&lt;span&gt; o&lt;/span&gt;&lt;span&gt;f&lt;/span&gt;&lt;span&gt; the modern terminal &lt;/span&gt;&lt;span&gt;emulator&lt;/span&gt;&lt;/span&gt;&lt;a href="https://github.com/ghostty-org/ghostty"&gt;&lt;span&gt;&lt;span&gt;Ghostty&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span&gt;&lt;span&gt;was released&lt;/span&gt;&lt;span&gt;that patched &lt;/span&gt;&lt;span&gt;a&lt;/span&gt;&lt;span&gt; code &lt;/span&gt;&lt;span&gt;execution vulnerability&lt;/span&gt;&lt;span&gt;, now tracked as &lt;/span&gt;&lt;/span&gt;&lt;a href="https://github.com/ghostty-org/ghostty/security/advisories/GHSA-5hcq-3j4q-4v6p"&gt;&lt;span&gt;&lt;span&gt;CVE-2024-56803&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span&gt;&lt;span&gt;. &lt;/span&gt;&lt;span&gt;While terminals execute commands by design, t&lt;/span&gt;&lt;span&gt;his vulnerability &lt;/span&gt;&lt;span&gt;allowed &lt;/span&gt;&lt;span&gt;for &lt;/span&gt;&lt;span&gt;unintended command execution through the title reporting escape sequence &lt;code&gt;(&lt;/code&gt;&lt;/span&gt;&lt;/span&gt;&lt;code&gt;&lt;span&gt;&lt;span&gt;\e[21t&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;span&gt;&lt;span&gt;&lt;code&gt;)&lt;/code&gt;.&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=4452610&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.netsecurity.no%2Fen%2Ftechnical-blog%2Fcode-execution-through-ghostty-window-title&amp;amp;bu=https%253A%252F%252Fwww.netsecurity.no%252Fen%252Ftechnical-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 11 Feb 2025 09:17:17 GMT</pubDate>
      <guid>https://www.netsecurity.no/en/technical-blog/code-execution-through-ghostty-window-title</guid>
      <dc:date>2025-02-11T09:17:17Z</dc:date>
      <dc:creator>Siddharth Dushantha</dc:creator>
    </item>
    <item>
      <title>Cyber attacks: Surprisingly few know who to call when they're attacked</title>
      <link>https://www.netsecurity.no/en/technical-blog/cyberangrep-overraskende-f%C3%A5-vet-hvem-de-skal-ringe-n%C3%A5r-de-blir-angrepet</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/cyberangrep-overraskende-f%C3%A5-vet-hvem-de-skal-ringe-n%C3%A5r-de-blir-angrepet?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/netsecurity_toril%20jensvold%20pc%20svart%20hvitt%20liggende.jpg" alt="Woman sitting in front of a laptop" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;span class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_module" style=""&gt;&lt;/span&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/cyberangrep-overraskende-f%C3%A5-vet-hvem-de-skal-ringe-n%C3%A5r-de-blir-angrepet?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/netsecurity_toril%20jensvold%20pc%20svart%20hvitt%20liggende.jpg" alt="Woman sitting in front of a laptop" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;span class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_module" style=""&gt;&lt;/span&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=4452610&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.netsecurity.no%2Fen%2Ftechnical-blog%2Fcyberangrep-overraskende-f%C3%A5-vet-hvem-de-skal-ringe-n%C3%A5r-de-blir-angrepet&amp;amp;bu=https%253A%252F%252Fwww.netsecurity.no%252Fen%252Ftechnical-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Fri, 23 Aug 2024 14:54:46 GMT</pubDate>
      <guid>https://www.netsecurity.no/en/technical-blog/cyberangrep-overraskende-f%C3%A5-vet-hvem-de-skal-ringe-n%C3%A5r-de-blir-angrepet</guid>
      <dc:date>2024-08-23T14:54:46Z</dc:date>
      <dc:creator>Netsecurity</dc:creator>
    </item>
    <item>
      <title>No coincidence that we have become one of Norway's leading competence centers for Palo Alto Networks</title>
      <link>https://www.netsecurity.no/en/technical-blog/et-av-norges-fremste-kompetansehus-p%C3%A5-palo-alto-networks</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/et-av-norges-fremste-kompetansehus-p%C3%A5-palo-alto-networks?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/Featured%20image_PANW.jpg" alt="No coincidence that we have become one of Norway's leading competence centers for Palo Alto Networks" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;span class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_module" style=""&gt;&lt;/span&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/et-av-norges-fremste-kompetansehus-p%C3%A5-palo-alto-networks?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/Featured%20image_PANW.jpg" alt="No coincidence that we have become one of Norway's leading competence centers for Palo Alto Networks" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;span class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_module" style=""&gt;&lt;/span&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=4452610&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.netsecurity.no%2Fen%2Ftechnical-blog%2Fet-av-norges-fremste-kompetansehus-p%C3%A5-palo-alto-networks&amp;amp;bu=https%253A%252F%252Fwww.netsecurity.no%252Fen%252Ftechnical-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Fri, 23 Aug 2024 13:33:00 GMT</pubDate>
      <guid>https://www.netsecurity.no/en/technical-blog/et-av-norges-fremste-kompetansehus-p%C3%A5-palo-alto-networks</guid>
      <dc:date>2024-08-23T13:33:00Z</dc:date>
      <dc:creator>Netsecurity</dc:creator>
    </item>
    <item>
      <title>ANSI Escape Injection vulnerability in WinRAR</title>
      <link>https://www.netsecurity.no/en/technical-blog/ansi-escape-injection-s%C3%A5rbarhet-i-winrar</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/ansi-escape-injection-s%C3%A5rbarhet-i-winrar?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/serverrum.jpg" alt="serverrum" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;Overview of the update&lt;/h2&gt; 
&lt;p&gt;On February 28, 2024, RARLAB released an update for WinRAR, which fixed an ANSI escape injection vulnerability that I had found in the console versions of RAR and UnRAR, affecting versions 6.24 and earlier. This vulnerability, tracked as CVE-2024-33899 for Linux and Unix systems and CVE-2024-36052 for Windows, allowed attackers to spoof the file list or perform a local service attack (Linux and Unix only).&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/ansi-escape-injection-s%C3%A5rbarhet-i-winrar?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/serverrum.jpg" alt="serverrum" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;Overview of the update&lt;/h2&gt; 
&lt;p&gt;On February 28, 2024, RARLAB released an update for WinRAR, which fixed an ANSI escape injection vulnerability that I had found in the console versions of RAR and UnRAR, affecting versions 6.24 and earlier. This vulnerability, tracked as CVE-2024-33899 for Linux and Unix systems and CVE-2024-36052 for Windows, allowed attackers to spoof the file list or perform a local service attack (Linux and Unix only).&lt;/p&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=4452610&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.netsecurity.no%2Fen%2Ftechnical-blog%2Fansi-escape-injection-s%C3%A5rbarhet-i-winrar&amp;amp;bu=https%253A%252F%252Fwww.netsecurity.no%252Fen%252Ftechnical-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Fri, 23 Aug 2024 12:59:36 GMT</pubDate>
      <guid>https://www.netsecurity.no/en/technical-blog/ansi-escape-injection-s%C3%A5rbarhet-i-winrar</guid>
      <dc:date>2024-08-23T12:59:36Z</dc:date>
      <dc:creator>Siddharth Dushantha</dc:creator>
    </item>
    <item>
      <title>Memory consumption vulnerability in libvte (CVE-2024-37535)</title>
      <link>https://www.netsecurity.no/en/technical-blog/minneforbrukss%C3%A5rbarhet-i-libvte</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/minneforbrukss%C3%A5rbarhet-i-libvte?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/drift.png" alt="Memory consumption vulnerability in libvte (CVE-2024-37535)" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;Overview of the update&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;On March 15, 2024, GNOME released an update for libvte that fixed a memory consumption vulnerability, now known as CVE-2024-37535. This vulnerability affects many popular terminal emulators such as GNOME Terminal, XFCE Terminal and MATE Terminal that use libvte version 0.76.2 or older. This vulnerability can be exploited by an attacker to kill the Xorg session, which will cause the victim to lose all of their unsaved work.&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.netsecurity.no/en/technical-blog/minneforbrukss%C3%A5rbarhet-i-libvte?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.netsecurity.no/hubfs/drift.png" alt="Memory consumption vulnerability in libvte (CVE-2024-37535)" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;Overview of the update&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;On March 15, 2024, GNOME released an update for libvte that fixed a memory consumption vulnerability, now known as CVE-2024-37535. This vulnerability affects many popular terminal emulators such as GNOME Terminal, XFCE Terminal and MATE Terminal that use libvte version 0.76.2 or older. This vulnerability can be exploited by an attacker to kill the Xorg session, which will cause the victim to lose all of their unsaved work.&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=4452610&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.netsecurity.no%2Fen%2Ftechnical-blog%2Fminneforbrukss%C3%A5rbarhet-i-libvte&amp;amp;bu=https%253A%252F%252Fwww.netsecurity.no%252Fen%252Ftechnical-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Fri, 23 Aug 2024 12:55:55 GMT</pubDate>
      <guid>https://www.netsecurity.no/en/technical-blog/minneforbrukss%C3%A5rbarhet-i-libvte</guid>
      <dc:date>2024-08-23T12:55:55Z</dc:date>
      <dc:creator>Siddharth Dushantha</dc:creator>
    </item>
  </channel>
</rss>
